Privacy policy
Non-binding translation. This English version is provided for information only. Only the German version is legally binding: read the German version.
Information on the processing of your personal data in accordance with the GDPR.
1. Controller
The controller within the meaning of the GDPR is:
FHC+P GmbHWürmstraße 55
82166 Gräfelfing
Germany
Email: datenschutz@fhcp.de · Web: www.fhcp.de
2. Provision of the website and log files
Each time the website is accessed, our system automatically records data from the accessing computer (browser type and version, operating system, IP address, date and time of access, referrer). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in functionality and security). Log files are deleted after seven days at the latest or the IP address is anonymised. No analysis for marketing purposes takes place.
2a. Audience measurement with Matomo (cookieless)
For statistical analysis of usage, we use the self-hosted open-source software Matomo (servers in Germany, operated by us, no disclosure to third parties). In our setup, Matomo works without cookies and anonymises your IP address (truncated by 2 bytes). No cross-device tracking takes place. For these reasons, the measurement does not require consent under § 25(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG); the legal basis is Art. 6(1)(f) GDPR (legitimate interest in data-minimising audience measurement).
You can object to the measurement at any time, directly here:
2b. Google Ads conversion measurement (server-side)
If you reach us via a Google ad, Google appends a click identifier (gclid) to the target address. We store this exclusively in the technically necessary session and, if you sign up, for a limited period with your account, in order to inform Google Ads that an ad click has resulted in a sign-up or a purchase (conversion measurement). The transmission to Google is carried out server-side by us; in doing so, we transmit the click identifier together with the time and, where applicable, the value of the conversion. No cookies are stored on or read from your device, so the storage and access requirement of § 25 TDDDG is not triggered, and no cross-device profile is created. However, the server-side approach does not replace consent: we treat the disclosure to Google as a separate processing operation and, when uploading, transmit the consent signals required by Google (ad user data, personalisation). As long as you have not given consent, these signals are transmitted as "not specified", so that Google uses your click only for aggregated, non-personal modelling. The legal basis for server-side performance measurement is Art. 6(1)(f) GDPR (legitimate interest in measuring the performance of our advertising); you have a right to object under Art. 21 GDPR against this legitimate interest. The recipient is Google Ireland Limited; a transfer of data to the USA (Google LLC) on the basis of the EU Standard Contractual Clauses or the EU-US Data Privacy Framework is possible. You can prevent this measurement by not accessing our website via an ad link or by objecting by email; a stored click identifier is also discarded when the session expires.
2c. LinkedIn Ads conversion measurement (server-side)
If you reach us via a LinkedIn ad, LinkedIn appends a click identifier (li_fat_id) to the target address. We store this, together with the identifier of the advertising campaign, exclusively in the technically necessary session and, if you sign up, with your account, in order to inform LinkedIn that an ad click has resulted in a sign-up or a purchase (conversion measurement). The transmission is carried out server-side by us via the ad management system Personativ operated by us; only the click identifier, the campaign identifier, the time and, where applicable, the value of the conversion are transmitted, not your email address. No cookies are stored on or read from your device (§ 25 TDDDG), and no cross-device profile is created. The server-side approach does not replace consent; we treat the disclosure to LinkedIn as a separate processing operation. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in measuring the performance of our advertising); you have a right to object under Art. 21 GDPR. The recipient is LinkedIn Ireland Unlimited Company; a transfer of data to the USA (LinkedIn Corporation) on the basis of the EU Standard Contractual Clauses or the EU-US Data Privacy Framework is possible. You can prevent this measurement by not accessing our website via an ad link or by objecting by email; a click identifier stored only in the session is discarded when the session expires.
3. User account and sign-up
To use the service, you create an account. We process your email address, a cryptographic hash of your password and API keys generated by you (stored exclusively as a hash). For billing and abuse prevention, we keep a usage log (time, endpoint called, status code, consumption). The legal basis is Art. 6(1)(b) GDPR (performance of a contract). To confirm your email address, we send a confirmation link.
3a. Free quick check (/pruefen) and email newsletter
For the free quick check without an account, you provide your email address; we use it to show you the check result. The legal basis is Art. 6(1)(b) GDPR (carrying out the check you requested) and Art. 6(1)(f) GDPR (abuse prevention, limiting the number of free checks). The checked file itself is processed exclusively for the check and is not stored.
In addition, you can voluntarily consent to receiving practical tips and news about e-invoicing by email. This consent is not a condition for the check: you receive the result in any case. The legal basis is Art. 6(1)(a) GDPR and § 7(2) no. 3 of the German Act against Unfair Competition (UWG). We use the double opt-in procedure: after you provide your address, you receive an email with a confirmation link; only after you have opened it do we send you information. As proof of consent, we store the time, the IP address and the wording you agreed to. You can withdraw your consent at any time with effect for the future, via the unsubscribe link in every email or informally to the address given below. After withdrawal, your address remains on a block list so that you are not contacted again by mistake.
4. Processing of your invoice data
Invoices created via the web interface are stored in your account as an invoice history (invoice data such as parties, line items and amounts) so that you can view and download the invoices again later. The legal basis is Art. 6(1)(b) GDPR (performance of a contract); in addition, statutory retention obligations (e.g. § 147 of the German Fiscal Code, AO) may apply. You can have individual invoices or your account deleted.
Pure API calls (e.g. /v1/cii, /v1/generate, /v1/validate, /v1/extract) process the transmitted content exclusively to carry out the respective call and do not store it permanently; it is discarded after the response. The only data retained permanently here are the metadata of the usage log (section 3, without invoice content) and, exclusively to prevent duplicate invoice numbers, the invoice number assigned per account (only the number, no invoice content). Validation takes place locally on our systems using the official KoSIT validator; no data is transmitted to third parties in the process.
Profile and customer master data: Sender details stored in your account (company, address, tax numbers, logo, footer and header) as well as customers and recipients saved by you (company, address, VAT ID, contact details) are stored to prefill and manage your invoices. The legal basis is Art. 6(1)(b) GDPR. You can change or delete this data at any time.
AI-assisted import (optional): If you use the AI mapping, the data you enter is transmitted to Mistral AI (Mistral AI SAS, France) for processing. Processing takes place within the EU; no transfer to a third country takes place. Use is voluntary; without this function, no such transfer takes place. The legal basis is Art. 6(1)(b) GDPR. Creating, checking and storing your invoices takes place exclusively on our systems in Germany.
5. Payment processing (Stripe)
For paid services, we use the payment service provider Stripe (Stripe Payments Europe, Ltd., Ireland). When you make a purchase, the data required for payment (including email address and payment details) is processed directly by Stripe; we do not receive your complete payment method details. The legal basis is Art. 6(1)(b) GDPR. Details: stripe.com/privacy.
6. Hosting
The service is operated in a data centre in Germany (Hetzner Online GmbH). A data processing agreement pursuant to Art. 28 GDPR has been concluded with the hosting provider. Processing and storage of the data, including backups, take place exclusively on servers within the EU. The legal basis is Art. 6(1)(f) GDPR (secure and stable operation).
7. Processing of your data on your behalf
Insofar as you process personal data of third parties via the service (e.g. of your own customers or invoice recipients), you are the controller for this and FHC+P GmbH is the processor. For this purpose, we provide a data processing agreement (Art. 28 GDPR). The technical and organisational measures include, among others, transport encryption (TLS/HTTPS), access controls, account-based data separation and regular, integrity-checked backups.
8. Cookies
We use a technically necessary session cookie to keep you logged in for the duration of the session. We do not use tracking or marketing cookies. The legal basis is Art. 6(1)(f) GDPR. The fonts used are delivered locally from our server; there is no connection to third-party providers (e.g. Google Fonts).
9. Rights of the data subject
You have the following rights with respect to the controller:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Withdrawal of consent given, with effect for the future
10. Right to lodge a complaint
Without prejudice to any other legal remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work or place of the alleged infringement.
11. Contact
If you have any questions about data protection, you can reach us at datenschutz@fhcp.de.